CVE-2021-34523
CRITICAL KEV RANSOMWAREMicrosoft Exchange Server - Privilege Escalation
Title source: llmDescription
Microsoft Exchange Server Elevation of Privilege Vulnerability
Exploits (9)
nomisec
SCANNER
16 stars
by mithridates1313 · infoleak
https://github.com/mithridates1313/ProxyShell_POC
metasploit
WORKING POC
EXCELLENT
by Orange Tsai, Jang (@testanull), PeterJson, brandonshi123, mekhalleh (RAMELLA Sébastien), Donny Maasland, Rich Warren, Spencer McIntyre, wvu · rubypocwindows
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/exchange_proxyshell_rce.rb
References (4)
Scores
CVSS v3
9.0
EPSS
0.9400
EPSS Percentile
99.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Exploitation Intel
CISA KEV
2021-11-03
VulnCheck KEV
2021-08-30
InTheWild.io
2021-08-24
ENISA EUVD
EUVD-2021-21177
Ransomware Use
Confirmed
Classification
Status
published
Affected Products (5)
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
microsoft/exchange_server
Timeline
Published
Jul 14, 2021
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026